// 2 ZERO-DAY · 3 CVE · 1 EXPLOIT · 1 ADVISORY IN THE LAST 24H
From January to April 2026, the Spring Ring campaign impersonated IT help desk staff on Microsoft Teams to trick employees into running RMM tools and custom malware, with escalation to NTLM relay attacks against domain controllers.

Between January and April 2026, a social engineering operation dubbed Spring Ring leveraged external Microsoft Teams accounts to impersonate IT help desk personnel, initiate voice phishing calls, and coerce employees into executing remote monitoring and management tools or custom malware. Palo Alto Networks' Unit 42 documented the campaign with telemetry covering more than 150 employees contacted across at least 10 organizations. The report reveals that in some cases the attackers pivoted from the call to an NTLM relay attack against the domain controller, compressing the path from a single compromise to domain control.

Key Takeaways
  • Spring Ring contacted more than 150 employees across at least 10 organizations between January and April 2026, impersonating IT staff on Microsoft Teams
  • Successful vishing calls typically lasted 10–15 minutes, with multiple attempts and voicemails left for targets
  • Attackers used .onmicrosoft.com tenants with names crafted to mimic legitimate infrastructure, such as ITProtectionDepartment and MandatoryNetworkMonitoring
  • In an advanced variant, the phone call escalated into an NTLM relay attack against the domain controller using open-source tools

How It Works: The Deception Chain on Teams

The campaign exploited Teams' "Chat with Anyone" feature, which by default allows external users to start conversations. Attackers created .onmicrosoft.com tenants with names designed to evoke internal IT structures: ithelp@InternalSystemsDaily[.]onmicrosoft[.]com, HelpDesk@ITProtectionDepartment[.]onmicrosoft[.]com, itadmin@MandatoryNetworkMonitoring[.]onmicrosoft[.]com, Internal@InternalUSAHelpDeskIT[.]onmicrosoft[.]com, ithelpdesk@CertifiedUpdateNetwork[.]onmicrosoft[.]com. This architectural choice exploits a perceptual asymmetry: users are trained to distrust email, but tend to treat chats on corporate platforms as inherently safe.

As Unit 42 documented, "what seems like a benign chat is in fact a voice phishing (vishing) call, during which adversaries try to coerce victims into executing remote monitoring and management (RMM) tools or custom malware." The attack identities included names of real industry personnel, partially redacted in the report for privacy. The calls required active voice interaction, not passive links—a paradigm shift from traditional phishing.

Unit 42 found no Microsoft product vulnerability related to this campaign. The attack works by design, not by flaw: the combination of open federation and lack of voice call monitoring on Teams created a vector that email security tools do not intercept.

Two Campaigns, Two Payloads: From RMM to Custom Dropper

The report distinguishes two campaigns with different post-compromise tactics. Campaign A followed a "bring-your-own-tool" approach: attackers induced victims to run legitimate RMM software such as Quick Assist or third-party tools. Campaign B instead employed a custom dropper with obfuscation techniques, indicating greater complexity and more elaborate follow-on activity.

The transition between the two campaigns is not fully clear from the report. What emerges with certainty is that both depended on the initial human interaction: neither exploited software vulnerabilities or zero-days. This makes the campaign particularly resistant to traditional technical defenses, which focus on malware signatures and network anomalies.

From a Call to the Domain Controller: The NTLM Relay Escalation

The most concerning variant documented by Unit 42 shows how vishing on Teams can be just the first link in a longer chain. According to the report, "in a more advanced variant, attackers transitioned from a vishing call to a full-blown Microsoft NT LAN Manager (NTLM) relay attack aimed at an organization's domain controller (DC)." Attackers used open-source tools such as PetitPotam to force NTLM authentication and redirect it to servers under their control.

This mechanism is particularly insidious because it requires neither sophisticated malware nor days of lateral movement. As Unit 42 observed, "once the trust gap is crossed, the path to domain-level privileges via open-source tools like PetitPotam is short." The trust gap is the central point: a voice call on a platform considered internal creates credibility that bypasses technical controls.

The Quantified Trend: Teams as the New Attack Perimeter

Numbers collected by Palo Alto Networks and third parties indicate a redefinition of the risk perimeter. In the first four months of 2026, 42% of phishing alerts in Cortex originated from collaboration tools, up from 30% in the prior four-month period. According to data cited by Unit 42, KnowBe4 recorded a 41% increase in Teams-based attacks between October 2025 and March 2026. These data, while not specific to Spring Ring, corroborate the trend that made the operation possible.

"Spring Ring's approach relies on active human voice interaction. In this way, attackers can evade detection without a software exploit. Instead, they rely on exploiting the trust that employees place in software as a service (SaaS) collaboration platforms" — Unit 42, Palo Alto Networks

What to Do Now

The implications of Spring Ring are specific and measurable for organizations using Microsoft Teams with open federation. The report documents 26 distinct identities used to approach targets, all hosted on attacker-controlled .onmicrosoft.com tenants. This suggests that visibility into external tenants interacting with your Teams environment is a direct exposure indicator.

Successful vishing calls lasted 10–15 minutes, an interval that offers a behavioral detection window. Organizations can assess whether their logging systems capture the duration and frequency of calls from external contacts on collaboration platforms. The absence of this data, noted by Unit 42, reduces visibility into a vector that has already generated 42% of phishing alerts in the first four months of 2026.

The distinction between Campaign A and Campaign B has a practical implication: Campaign A used known legitimate RMM tools, while Campaign B employed a custom dropper. This difference indicates that allowlists for executed software must include not only recognized malicious tools, but also legitimate ones when launched at the behest of a user after external contact.

The NTLM relay escalation documented in the advanced variant shows that initial compromise on Teams can lead to domain-level privileges without traditional lateral movement chains. Organizations lacking visibility into NTLM authentications toward domain controllers expose a path that Spring Ring has already traversed.

The Line Between Trusted Platform and Attack Vector

Spring Ring highlights a structural shift in how attackers evaluate the attack surface. SaaS collaboration platforms are no longer alternative channels to email phishing: they are becoming the primary channel, exploiting a social trust that traditional security policies have yet to map. The human voice adds a layer of credibility that text cannot achieve, and the lack of detailed logging for voice calls on Teams reduces visibility for security teams.

The campaign sits in a continuum of Teams threats that includes operations attributed to APT29, but differs in method and intensity. If Teams phishing was previously associated with automated messages and malicious links, Spring Ring introduces human scale: long calls, multiple interactions, real-time adaptation to victim behavior. This shift demands a reassessment of security training models, still predominantly oriented toward recognizing suspicious emails rather than voice conversations on corporate platforms.

The potential escalation to NTLM relay against a domain controller is the strongest signal of how short the distance can be between a single individual compromise and control of corporate infrastructure. A complex lateral movement chain is unnecessary when initial trust is sufficient to legitimize the execution of tools that open the passage.

Sources

Information is based on the cited source and current as of publication.

Sources


Sources and references
  1. unit42.paloaltonetworks.com
  2. insidersecurity.co